#FactCheck- Viral video of burning ship falsely linked to US attack on vessel carrying Indian nationals in Oman waters
Executive Summary
Amid rising tensions in West Asia and concerns over the safety of Indian seafarers, a video showing a vessel engulfed in flames and thick black smoke is being widely circulated on social media. The clip is being shared with the claim that it depicts a US attack on a ship carrying Indian nationals in Omani waters. CyberPeace Research Wing research found the claim to be misleading. The viral video predates the incident it is being linked to and is not related to any recent attack.
Claim:
A Facebook user shared the video alleging that the United States attacked a ship carrying Indian citizens in the maritime region near Oman. The post has been widely circulated as part of the ongoing West Asia tensions. Facebook link: https://www.facebook.com/reel/3031094270427837, https://www.facebook.com/reel/3031094270427837

Fact Check:
A reverse image search of keyframes from the viral video led to several media reports published on 2 March 2026, which carried the same visuals seen in the circulating clip. The reports indicated that the footage showed a vessel targeted amid escalating tensions in the Strait of Hormuz, following restrictions on maritime movement in the region. https://www.ndtv.com/world-news/iran-targets-6th-ship-in-hormuz-strait-video-shows-billowing-smoke-11159019

Further research also found the same visuals in a Moneycontrol report published on 2 March 2026. The report clearly established that the footage is from an earlier incident and not linked to any recent developments. https://www.moneycontrol.com/world/indian-crew-member-killed-after-drone-boat-strikes-oil-tanker-off-oman-coast-first-indian-casualty-in-us-iran-tensions-article-13848303.html

Conclusion:
The research confirms that the viral video is not related to any recent US attack on a vessel carrying Indian nationals. The footage has been online since at least March 2026 and shows an earlier incident involving the oil tanker Skylight during tensions in the Strait of Hormuz. Hence, the claim being circulated on social media is misleading.
Related Blogs

CERT-In, India's national cybersecurity agency, operates under mounting pressure. Cyberattacks in the country have doubled from 1.4 million in FY2022 to 2.9 million in FY2026, even as the window between a vulnerability's discovery and its exploitation continues to narrow. Rather than wait for access to the most advanced AI security tools, some of which face export restrictions, the agency has spent recent months building its own solution.
CERT-In has developed a new sandbox platform built with open-source AI, designed to identify cybersecurity gaps in public-sector systems. The sandbox functions as an isolated testing environment, allowing teams to safely evaluate software and applications without exposing the broader system to risk. Officials have framed this as a foundation rather than a substitute. MeitY Secretary S Krishnan described the platform as a step toward building a secure environment for eventual access to international AI models — suggesting the current approach is understood as an interim measure, not a permanent alternative to global tools.
This effort sits within a broader policy push: encouraging domestic AI development and tightening oversight of AI use in finance and online content. Taken together, these moves suggest a deliberate strategy of capacity-building through incremental, self-reliant steps, rather than a story about capability gaps or resource shortfalls.
A Crisis Measured in Millions
It helps to look at why this matters so much right now. A joint study by the Data Security Council of India and BCG found that recorded cyberattacks in the country roughly doubled in four years, from about 1.4 million in FY22 to 2.9 million in FY26. What's more worrying is how little time defenders now have to react to the average time it takes attackers to exploit a newly found vulnerability dropped from 745 days in FY22 to just 44 days in FY26, largely because attackers are using AI themselves to scout targets and build exploits faster. Banking, financial services, healthcare, telecom and government portals bear the brunt of this, with ransomware-as-a-service groups and state-linked actors increasingly slipping in through vendor portals and supply-chain weak points.
Turning Existing AI Into a Working Defence
CERT-In's Sandbox in Action
Instead of treating the lack of any one frontier model as a dealbreaker, CERT-In simply built its own closed trial platform officials have taken to calling it a "war room" where open-source and other AI models are set loose on software code to find vulnerabilities and shape secure workflows for India's top public sector companies, including in financial services. At a press conference, Meity secretary S. Krishnan pointed out that these substitute models already match roughly 60 to 70 per cent of the performance of the most advanced security-focused systems out there globally. That's a fairly substantial chunk of the capability, and it's coming from tools India can actually access today. The testing has stretched to core digital infrastructure like Aadhaar and government login systems, while some of the country's biggest tech firms are already using currently available AI models to patch widely used enterprise software, banking platforms included. The logic is simple enough: build the muscle now with whatever's on hand, so the enterprise environment is already in better shape by the time more capable tools eventually arrive.
Investing in Sovereign Capability
Arguably the more important move here is a longer-term one , India's bet on building its own frontier-grade security AI. The Centre has reportedly asked domestic AI developers Sarvam AI and BharatGen to build advanced cybersecurity capabilities of their own, hosted on the government's isolated computer infrastructure and eventually put to work protecting critical infrastructure. There's no public timeline yet for when these indigenous models will be ready, but the intent behind the move isn't hard to read: cut India's reliance on any single foreign provider for defending the systems that underpin banking, identity and public administration, while keeping sensitive testing and deployment on Indian soil. Officials have also signalled a preference for on-premises deployment of high-capability AI tools where the stakes are highest, rather than leaning entirely on overseas cloud infrastructure. It's a choice that points toward building lasting, self-reliant capacity rather than making a one-off purchase.
A Tightening Regulatory Net
RBI's Model Risk Guardrails
None of this is happening in a vacuum. On 24 June 2026, the Reserve Bank of India released draft guidance on model risk management that, for the first time, brings AI and machine learning systems used by banks, NBFCs and other regulated entities under a single, board-level governance framework. The draft asks institutions to keep a full inventory of every model they use, rank each one by risk, and build in human override and "kill-switch" mechanisms so a malfunctioning AI system can be shut down immediately. It also makes one thing very clear: banks can't shrug off accountability just because the technology came from a vendor.
MeitY's Deepfake and Synthetic-Content Rules
Around the same time, the Ministry of Electronics and Information Technology notified amendments to the IT Rules that formally define "synthetically generated information," require deepfakes and AI-altered media to carry clear, persistent labels and embedded provenance metadata, and cut the takedown window for unlawful synthetic content down to just three hours. Taken together, the RBI and MeitY rules form the regulatory backbone that CERT-In's technical sandbox is meant to plug into giving India a more coordinated response to both the defensive and the deceptive sides of AI.
One Chain of Command
Officials have gone out of their way to stress that all these moving parts aren't creating confusion in India's cybersecurity reporting structure. CERT-In director general Sanjay Bahl has said the National Security Council Secretariat remains the overarching body, with CERT-In as the top cyber reporting and investigations organisation across sectors, and that sectoral regulators like the RBI and SEBI still report into this one structure rather than running their own parallel systems.
Conclusion
Look at CERT-In's sandbox, the push for sovereign AI, and the tightening regulatory net together, and a clearer picture forms. This isn't really a story about a piece of technology India doesn't have. It's a story about capability being built, deliberately and in the open. The country is using the AI tools available right now to close real security gaps, backing homegrown alternatives for the long haul, and pairing both with governance rules that keep banks, platforms and public infrastructure honest. If there's a lesson in all this, it's that real resilience against a fast-moving cyberthreat landscape rarely arrives all at once. It gets built the way most lasting capability does piece by piece, mostly at home, without waiting for any single outside breakthrough to show up first.
References
- https://inc42.com/buzz/centre-asks-sarvam-ai-bharatgen-to-develop-mythos-like-cyber-ai-models/
- https://inc42.com/buzz/centre-asks-sarvam-ai-bharatgen-to-develop-mythos-like-cyber-ai-models/
- https://www.newkerala.com/news/a/govt-prioritises-access-anthropics-mythos-ai-model-strengthen-475.htm
- https://blog.qualys.com/product-tech/2026/06/24/cert-in-ai-vulnerability-blueprint-machine-speed-risk-operations
- https://www.business-standard.com/technology/tech-news/mythos-threat-govt-tech-firms-test-their-softwares-for-vulnerabilities-126052700386_1.html
- https://inc42.com/buzz/centre-asks-sarvam-ai-bharatgen-to-develop-mythos-like-cyber-ai-models/
- https://www.finextra.com/blogposting/32142/rbis-model-risk-management-guidance-2026--summary
- https://www.medianama.com/2026/06/223-rbi-ai-guidelines-2026-banks-kill-switch/
- https://www.freshfields.com/en/our-thinking/blogs/technology-quotient/india-targets-deepfakes-and-ai-generated-content-key-changes-under-meitys-2026-102mjwn
.webp)
Introduction:
The Federal Bureau of Investigation (FBI) focuses on threats and is an intelligence-driven agency with both law enforcement and intelligence responsibilities. The FBI has the power and duty to look into certain offences that are entrusted to it and to offer other law enforcement agencies cooperation services including fingerprint identification, lab tests, and training. In order to support its own investigations as well as those of its collaborators and to better comprehend and address the security dangers facing the United States, the FBI also gathers, disseminates, and analyzes intelligence.
The FBI’s Internet Crime Complaint Center (IC3) Functions combating cybercrime:
- Collection: Internet crime victims can report incidents and notify the relevant authorities of potential illicit Internet behavior using the IC3. Law enforcement frequently advises and directs victims to use www.ic3.gov to submit a complaint.
- Analysis: To find new dangers and trends, the IC3 examines and examines data that users submit via its website.
- Public Awareness: The website posts public service announcements, business alerts, and other publications outlining specific frauds. Helps to raise awareness and make people become aware of Internet crimes and how to stay protected.
- Referrals: The IC3 compiles relevant complaints to create referrals, which are sent to national, international, local, and state law enforcement agencies for possible investigation. If law enforcement conducts an investigation and finds evidence of a crime, the offender may face legal repercussions.
Alarming increase in cyber crime cases:
In the recently released 2022 Internet Crime Report by the FBI's Internet Crime Complaint Center (IC3), the statistics paint a concerning picture of cybercrime in the United States. FBI’s Internet Crime Complaint Center (IC3) received 39,416 cases of extortion in 2022. The number of cases in 2021 stood at 39,360.
FBI officials emphasize the growing scope and sophistication of cyber-enabled crimes, which come from around the world. They highlight the importance of reporting incidents to IC3 and stress the role of law enforcement and private-sector partnerships.
About Internet Crime Complaint Center IC3:
IC3 was established in May 2000 by the FBI to receive complaints related to internet crimes.
It has received over 7.3 million complaints since its inception, averaging around 651,800 complaints per year over the last five years. IC3's mission is to provide the public with a reliable reporting mechanism for suspected cyber-enabled criminal activity and to collaborate with law enforcement and industry partners.
The FBI encourages the public to regularly review consumer and industry alerts published by IC3. An victim of an internet crime are urged to submit a complaint to IC3, and can also file a complaint on behalf of another person. These statistics underscore the ever-evolving and expanding threat of cybercrime and the importance of vigilance and reporting to combat this growing challenge.
What is sextortion?
The use or threatened use of a sexual image or video of another person without that person’s consent, derived from online encounters or social media websites or applications, primarily to extort money from that person or asking for sexual favours and giving warning to distribute that picture or video to that person’s friends, acquaintances, spouse, partner, or co-workers or in public domain.
Sextortion is an online crime that can be understood as, when an bad actor coerces a young person into creating or sharing a sexual image or video of themselves and then uses it to get something from such young person, such as other sexual images, money, or even sexual favours. Reports highlights that more and more kids are being blackmailed in this way. Sextortion can also happen to adults. Sextortion can also take place by taking your pictures from social media account and converting those pictures into sexually explicit content by morphing such images or creating deepfake by miusing deepfake technologies.
Sextortion in the age of AI and advanced technologies:
AI and deep fake technology make sextortion even more dangerous and pernicious. A perpetrator can now produce a high-quality deep fake that convincingly shows a victim engaged in explicit acts — even if the person has not done any such thing.
Legal Measures available in cases of sextortion:
In India, cybersecurity is governed primarily by the Indian Penal Code (IPC) and the Information Technology Act, 2000 (IT Act). Addressing cyber crimes such as hacking, identity theft, and the publication of obscene material online, sextortion and other cyber crimes. The IT Act covers various aspects of electronic governance and e-commerce, with providing provisions for defining such offences and providing punishment for such offences.
Recently Digital Personal Data Protection Act, 2023 has been enacted by the Indian Government to protect the digital personal data of the Individuals. These laws collectively establish the legal framework for cybersecurity and cybercrime prevention in India. Victims are urged to report the crime to local law enforcement and its cybercrime divisions. Law enforcement will investigate sextortion cases reports and will undertake appropriate legal action.
How to stay protected from evolving cases of sextortion: Best Practices:
- Report the Crime to law enforcement agency and social media platform or Internet service provider.
- Enable Two-step verification as an extra layer of protection.
- Keep your laptop Webcams covered when not in use.
- Stay protected from malware and phishing Attacks.
- Protect your personal information on your social media account, and also monitor your social media accounts in order to identify any suspicious activity. You can also set and review privacy settings of your social media accounts.
Conclusion:
Sextortion cases has been increased in recent time. Knowing the risk, being aware of rules and regulations, and by following best practices will help in preventing such crime and help you to stay safe and also avoid the chance of being victimized. It is important to spreading awareness about such growing cyber crimes and empowering the people to report it and it is also significant to provide support to victims. Let’s all unite in order to fight against such cyber crimes and also to make life a safer place on the internet or digital space.
References:
- https://www.ic3.gov/Media/PDF/AnnualReport/2022_IC3ElderFraudReport.pdf
- https://octillolaw.com/insights/fbi-ic3-releases-2022-internet-crime-report/
- https://www.iafci.org/app_themes/docs/Federal%20Agency/2022_IC3Report.pdf

Introduction
In a world where Artificial Intelligence (AI) is already changing the creation and consumption of content at a breathtaking pace, distinguishing between genuine media and false or doctored content is a serious issue of international concern. AI-generated content in the form of deepfakes, synthetic text and photorealistic images is being used to disseminate misinformation, shape public opinion and commit fraud. As a response, governments, tech companies and regulatory bodies are exploring ‘watermarking’ as a key mechanism to promote transparency and accountability in AI-generated media. Watermarking embeds identifiable information into content to indicate its artificial origin.
Government Strategies Worldwide
Governments worldwide have pursued different strategies to address AI-generated media through watermarking standards. In the US, President Biden's 2023 Executive Order on AI directed the Department of Commerce and the National Institute of Standards and Technology (NIST) to establish clear guidelines for digital watermarking of AI-generated content. This action puts a big responsibility on large technology firms to put identifiers in media produced by generative models. These identifiers should help fight misinformation and address digital trust.
The European Union, in its Artificial Intelligence Act of 2024, requires AI-generated content to be labelled. Article 50 of the Act specifically demands that developers indicate whenever users engage with synthetic content. In addition, the EU is a proponent of the Coalition for Content Provenance and Authenticity (C2PA), an organisation that produces secure metadata standards to track the origin and changes of digital content.
India is currently in the process of developing policy frameworks to address AI and synthetic content, guided by judicial decisions that are helping shape the approach. In 2024, the Delhi High Court directed the central government to appoint members for a committee responsible for regulating deepfakes. Such moves indicate the government's willingness to regulate AI-generated content.
China, has already implemented mandatory watermarking on all deep synthesis content. Digital identifiers must be embedded in AI media by service providers, and China is one of the first countries to adopt stern watermarking legislation.
Understanding the Technical Feasibility
Watermarking AI media means inserting recognisable markers into digital material. They can be perceptible, such as logos or overlays or imperceptible, such as cryptographic tags or metadata. Sophisticated methods such as Google's SynthID apply imperceptible pixel-level changes that remain intact against standard image manipulation such as resizing or compression. Likewise, C2PA metadata standards enable the user to track the source and provenance of an item of content.
Nonetheless, watermarking is not an infallible process. Most watermarking methods are susceptible to tampering. Aforementioned adversaries with expertise, for instance, can use cropping editing or AI software to delete visible watermarks or remove metadata. Further, the absence of interoperability between different watermarking systems and platforms hampers their effectiveness. Scalability is also an issue enacting and authenticating watermarks for billions of units of online content necessitates huge computational efforts and routine policy enforcement across platforms. Scientists are currently working on solutions such as blockchain-based content authentication and zero-knowledge watermarking, which maintain authenticity without sacrificing privacy. These new techniques have potential for overcoming technical deficiencies and making watermarking more secure.
Challenges in Enforcement
Though increasing agreement exists for watermarking, implementation of such policies is still a major issue. Jurisdictional constraints prevent enforceability globally. A watermarking policy within one nation might not extend to content created or stored in another, particularly across decentralised or anonymous domains. This creates an exigency for international coordination and the development of worldwide digital trust standards. While it is a welcome step that platforms like Meta, YouTube, and TikTok have begun flagging AI-generated content, there remains a pressing need for a standardised policy that ensures consistency and accountability across all platforms. Voluntary compliance alone is insufficient without clear global mandates.
User literacy is also a significant hurdle. Even when content is properly watermarked, users might not see or comprehend its meaning. This aligns with issues of dealing with misinformation, wherein it's not sufficient just to mark off fake content, users need to be taught how to think critically about the information they're using. Public education campaigns, digital media literacy and embedding watermarking labels within user-friendly UI elements are necessary to ensure this technology is actually effective.
Balancing Privacy and Transparency
While watermarking serves to achieve digital transparency, it also presents privacy issues. In certain instances, watermarking might necessitate the embedding of metadata that will disclose the source or identity of the content producer. This threatens journalists, whistleblowers, activists, and artists utilising AI tools for creative or informative reasons. Governments have a responsibility to ensure that watermarking norms do not violate freedom of expression or facilitate surveillance. The solution is to achieve a balance by employing privacy-protection watermarking strategies that verify the origin of the content without revealing personally identifiable data. "Zero-knowledge proofs" in cryptography may assist in creating watermarking systems that guarantee authentication without undermining user anonymity.
On the transparency side, watermarking can be an effective antidote to misinformation and manipulation. For example, during the COVID-19 crisis, misinformation spread by AI on vaccines, treatments and public health interventions caused widespread impact on public behaviour and policy uptake. Watermarked content would have helped distinguish between authentic sources and manipulated media and protected public health efforts accordingly.
Best Practices and Emerging Solutions
Several programs and frameworks are at the forefront of watermarking norms. Adobe, Microsoft and others' collaborative C2PA framework puts tamper-proof metadata into images and videos, enabling complete traceability of content origin. SynthID from Google is already implemented on its Imagen text-to-image model and secretly watermarks images generated by AI without any susceptibility to tampering. The Partnership on AI (PAI) is also taking a leadership role by building out ethical standards for synthetic content, including standards around provenance and watermarking. These frameworks become guides for governments seeking to introduce equitable, effective policies. In addition, India's new legal mechanisms on misinformation and deepfake regulation present a timely point to integrate watermarking standards consistent with global practices while safeguarding civil liberties.
Conclusion
Watermarking regulations for synthetic media content are an essential step toward creating a safer and more credible digital world. As artificial media becomes increasingly indistinguishable from authentic content, the demand for transparency, origin, and responsibility increases. Governments, platforms, and civil society organisations will have to collaborate to deploy watermarking mechanisms that are technically feasible, compliant and privacy-friendly. India is especially at a turning point, with courts calling for action and regulatory agencies starting to take on the challenge. Empowering themselves with global lessons, applying best-in-class watermarking platforms and promoting public awareness can enable the nation to acquire a level of resilience against digital deception.
References
- https://artificialintelligenceact.eu/
- https://www.cyberpeace.org/resources/blogs/delhi-high-court-directs-centre-to-nominate-members-for-deepfake-committee
- https://c2pa.org
- https://www.cyberpeace.org/resources/blogs/misinformations-impact-on-public-health-policy-decisions
- https://deepmind.google/technologies/synthid/
- https://www.imatag.com/blog/china-regulates-ai-generated-content-towards-a-new-global-standard-for-transparency